
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@go-corp/ui
Advanced tools
=====================================
The official UI component library for Go Corp, designed to provide a consistent and cohesive user experience across all development projects.
This library provides a set of reusable UI components, built with a focus on accessibility, performance, and customization. It is intended to be used as a foundation for all Go Corp projects, ensuring a unified visual language and streamlined development process.
To get started with the Go Corp UI component library, install the @go-corp/ui package using npm or yarn:
npm install @go-corp/ui
or
yarn add @go-corp/ui
Import the desired components into your project and use them as needed. For example:
import {Button} from '@go-corp/ui';
<Button>Click me</Button>
The Go Corp UI component library includes a wide range of components, such as:
For detailed documentation on each component, including props, usage examples, and accessibility features, please refer to the Component Documentation page.
The Go Corp UI component library is designed to be highly customizable. You can override the default styles and theme using CSS variables or by providing a custom theme object.
For more information on customizing the theme, please refer to the Theme Documentation page.
We welcome contributions to the Go Corp UI component library. If you're interested in contributing, please read our Contributing Guidelines and submit a pull request.
The Go Corp UI component library is licensed under the MIT License.
For a list of changes and updates, please refer to the Changelog page.
This `README.md` file provides a brief overview of the UI component library, installation instructions, usage examples, and links
FAQs
=====================================
We found that @go-corp/ui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.